首页> 外文会议>International Conference on Information Technologies >Organisational Information Security Maturity Assessment Based on ISO 27001 and ISO 27002
【24h】

Organisational Information Security Maturity Assessment Based on ISO 27001 and ISO 27002

机译:基于ISO 27001和ISO 27002的组织信息安全成熟度评估

获取原文

摘要

This article proposes a practical methodology for performing information security maturity assessment for organisations which operate an Information Security Management System (ISMS) based on the ISO 27001:2013 standard. The methodology uses a COBIT 5-comparable method to evaluate the maturity level of the security controls and clauses in ISO 27001:2013 and leverages on the guidelines in ISO 27002:2013. It was successfully used in an undisclosed company. Information security professionals can benefit from applying the same methodology or a similar one in organisations of various size and nature. The final product of the assessment is metrics and recommendations for improvement of the ISMS, which can be used for tactical and strategic decision-making, as well as input for organisational information security risk management.
机译:本文提出了对基于ISO 27001:2013标准进行信息安全管理系统(ISMS)的组织执行信息安全成熟度评估的实用方法。该方法使用Cobit 5比较方法来评估ISO 27001:2013中安全控制和条款的成熟度水平,并利用ISO 27002:2013的指南。它已成功用于未公开的公司。信息安全专业人员可以从各种规模和自然的组织中应用相同的方法或类似的方法。评估的最终产品是指标和提出改进ISM的建议,可用于战术和战略决策,以及组织信息安全风险管理的投入。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号